Malware & Threats

Massive 911 S5 Botnet Dismantled, Chinese Mastermind Arrested

The US announced that the 911 S5 (Cloud Router) botnet, likely the world’s largest, has been dismantled and its administrator arrested.

911 S5 botnet dismantled

The US Justice Department announced on Wednesday that the massive 911 S5 proxy botnet has been dismantled and its alleged administrator, a Chinese national, has been arrested.

The Treasury Department earlier this week announced sanctions against three Chinese nationals accused of being involved in the creation and operation of the 911 S5 botnet. 

The sanctions targeted Yunhe Wang, Jingping Liu, and Yanni Zheng, as well as three Thailand-based companies that are allegedly owned or controlled by Wang.  

One day later, the Justice Department announced that 35-year-old Wang, who is allegedly the administrator of the botnet, was in fact arrested on May 24 and the botnet was dismantled

Cybersecurity blogger Brian Krebs detailed the 911 S5 botnet back in 2022, naming Wang as the owner. 911 S5 was shut down by its operators shortly after, but reemerged in October 2023 as Cloud Router, which also ceased operations just days before the US government announced targeting the botnet and its administrators. 

The Justice Department revealed on Wednesday that the botnet was disrupted as part of an international law enforcement operation involving agencies from the US, Germany, Singapore and Thailand. The operation included the seizure of 23 domains and over 70 servers used by the 911 S5 botnet and its successor, Cloud Router. 

Advertisement. Scroll to continue reading.

911 S5 (and Cloud Router), described by the FBI’s director as “likely the world’s largest botnet”, ensnared 19 million Windows devices across over 190 countries between 2014 and 2022. The malware that powered the botnet was delivered alongside ‘free’ VPN applications, enabling the botnet’s operators to use compromised devices as proxies without their owners’ knowledge. 

These proxies were used to disguise the origin of a wide range of malicious activities, including cyberattacks, fraud, bomb threats, child exploitation, and export violations. 

“The 911 S5 client interface software, which was hosted on U.S.-based servers, enabled cybercriminals located outside of the United States to purchase goods with stolen credit cards or criminally derived proceeds, and illegally export them outside of the United States,” the DoJ said.

Wang has been charged with conspiracy to commit computer fraud, substantive computer fraud, conspiracy to commit wire fraud, and conspiracy to commit money laundering, and faces up to 65 years in prison.

According to the indictment, the Chinese national received roughly $99 million from the sale of proxied IP addresses between 2018 and 2022. He allegedly used some of the money to buy real estate in the United States, St. Kitts and Nevis, China, Singapore, Thailand, and the United Arab Emirates, as well as several luxury vehicles. Authorities have seized approximately $30 million worth of assets and identified forfeitable property valued at an additional $30 million. 

Wang was arrested in Singapore and is awaiting extradition to the United States. 

The FBI has provided instructions on how users can check their devices for the presence of the malicious VPN applications and how to remove them. 

Related: Botnet Disrupted by FBI Still Used by Russian Spies, Cybercriminals

Related: US Says It Disrupted a China Cyber Threat, but Warns Hackers Could Still Wreak Havoc for Americans

Related: 400,000 Linux Servers Hit by Ebury Botnet

Related: Researchers Discover 40,000-Strong EOL Router, IoT Botnet 

Related Content

Cybercrime

Hundreds of C&C servers were disrupted in an operation involving law enforcement and several cybersecurity companies.

Malware & Threats

Law enforcement and private partners took down 106 SocGholish C&C servers and domains as part of Operation Endgame.

Government

The 13 websites purported to be affiliated with consulting companies that advertised job openings for current and former holders of security clearances

Cybercrime

Law enforcement and tech companies disrupted infrastructure linked to scammers operating across Southeast Asia.

Cybercrime

Dutch authorities seized command-and-control servers tied to a botnet of infected computers, smartphones, and tablets that was allegedly used to power a residential proxy...

Malware & Threats

Security firms took down all four command-and-control (C&C) channels used by the GlassWorm malware.

Cybercrime

Jacob Butler, 23, has been arrested in Canada and US authorities are seeking his extradition on computer hacking charges.

Cybercrime

The FBI says First VPN has been used by dozens of ransomware groups for network reconnaissance and intrusions.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version